Four critical and important Apache Impala vulnerabilities expose analytical database clusters to remote code execution and data...
Authentication Bypass
Siemens ProductCERT disclosed two critical Siemens vulnerabilities on September 8, 2026. One allows full account takeover in...
TL;DR FreeRDP 3.31.0 patches five server-role flaws reported by Bynario, plus 17 other issues. Researchers chained three...
TL;DR Proxmox published advisory PSA-2026-00043-1 on September 1, 2026. It warns of a critical Proxmox VE authentication...
TL;DR A critical Artifactory authentication bypass vulnerability allows unauthenticated threat actors to obtain administrative privileges. Security researchers...
TL;DR The Apache Tomcat team fixed 11 vulnerabilities on August 25, 2026. The batch includes three Important...
TL;DR CISA disclosed 11 Ebyte NE2-D11 vulnerabilities on August 25, 2026. Four carry a critical 9.8 CVSS...
TL;DR CERT/CC disclosed five RDK-B WebUI vulnerabilities on August 19, 2026. The worst flaw lets a remote,...
CVE-2026-20315 & CVE-2026-20317: Cisco Secure Workload Auth Bypass, Privilege Escalation Hit CVSS 10
CVE-2026-20315 & CVE-2026-20317: Cisco Secure Workload Auth Bypass, Privilege Escalation Hit CVSS 10
TL;DR Cisco released hardening updates for Secure Workload on August 19, 2026. The Cisco Secure Workload authentication...
TL;DR Citrix patched a critical NetScaler authentication bypass tracked as CVE-2026-19490. It scores 9.3 on CVSS v4....
IBM patched 18 flaws in Db2 Mirror for i this week. The worst bug lets a remote...
TL;DR: A critical User Profile Builder vulnerability, carrying a maximum CVSS score of 9.8 and tracked as...
TL;DR TP-Link disclosed five vulnerabilities across its ISP-managed networking gear. The flaws hit mesh systems, routers, PON...
TL;DR HPE Aruba Networking patched two critical flaws in its SD-WAN EdgeConnect Orchestrator. Both carry a CVSS...
TL;DR Two critical Puwell IP Camera vulnerabilities now have public details and proof-of-concept exploit code. Both score...
TL;DR Rapid7 has published a technical analysis and a working proof-of-concept for CVE-2026-55040. The flaw is a...
TL;DR Progress released an August 2026 bulletin for MarkLogic Server. It fixes ten MarkLogic Server vulnerabilities, several...
TL;DR A high-severity authentication bypass affects the Neo4j GraphQL Library before versions 7.5.6 and 5.12.14. Tracked as...
TL;DR WSO2 disclosed four critical vulnerabilities across its API and identity products. Several are WSO2 account takeover...
TL;DR: Attackers are actively exploiting a N-central account takeover flaw tracked as CVE-2026-18577. N-able says an incomplete...
TL;DR: Check Point patched a Check Point authentication bypass affecting its Security Management and Multi-Domain Security Management...
TL;DR CERT/CC disclosed an Arris BGW210-700 vulnerability tracked as CVE-2026-16771. The authentication bypass affects firmware 2.7.7 and...